Privacy Policy

We are very pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g. via a cookie banner).

We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.

We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.

This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China's Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.

For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.

If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E..

1. Definitions

In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.

The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.

We use the following terms, among others, in this Privacy Policy:

a) Personal Data

Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.

b) Data Subject

Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.

c) Processing

Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

d) Restriction of Processing

Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.

e) Profiling

Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

f) Pseudonymization

Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.

g) Controller

The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.

h) Processor

A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.

i) Recipient

A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.

j) Third Party

A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.

k) Consent

Consent is any freely given, specific, informed and unambiguous indication of the Data Subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.

2. Name and address of the Controller

The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:

LUT Entrepreneurship Society ry

Yliopistonkatu 34

53850 Lappeenranta

Phone.: +358 45 359 8244

eMail: info@lutes.fi

Website: https://lutes.fi

3. Collection of general data and information

Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.

When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.

The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.

Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.

We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:

By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g. due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.

5. Routine deletion and restriction of Personal Data

We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.

If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.

6. Rights of the Data Subject according to GDPR

a) Right to confirmation

Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.

If a Data Subject wishes to exercise this right, he or she may contact us at any time.

b) Right to information

Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:

• the purposes of processing,

• the categories of Personal Data that are processed,

• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,

• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,

• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,

• the existence of a right to lodge a complaint with a supervisory authority,

• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,

• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.

Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.

If a Data Subject wishes to exercise this right, he or she may contact us at any time.

c) Right to rectification

Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.

If a Data Subject wishes to exercise this right, he or she may contact us at any time.

d) Right to erasure (right to be forgotten)

Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:

• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.

• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.

• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.

• Personal Data was processed unlawfully.

• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.

• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.

If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.

If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.

e) Right to Restriction of Processing

Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:

• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.

• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.

• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.

• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.

If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.

f) Right to data portability

Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.

Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.

If a Data Subject wishes to exercise this right, he or she may contact us at any time.

g) Right to object

Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.

In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.

If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.

In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.

If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.

h) Automated decisions in individual cases including Profiling

Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject's rights and freedoms and legitimate interests, or (3) is based on the Data Subject's explicit Consent.

If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject's explicit Consent, we shall implement suitable measures to safeguard the Data Subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.

If a Data Subject wishes to exercise this right, he or she may contact us at any time.

i) Right to withdraw Consent under data protection law

Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.

If a Data Subject wishes to exercise this right, he or she may contact us at any time.

7. General purpose of Processing, categories of processed data and categories of recipients

The general purpose of processing of Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.

The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.

A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.

Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.

In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.

If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.

Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).

9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing

If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.

We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.

10. Duration for which the Personal Data is stored

The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.

We would like to inform you that the provision of Personal Data is partly required by law (e.g. tax regulations) or may also result from contractual obligations (e.g. information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.

12. Existence of automated decision-making

As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:

Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.

In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject's rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.

Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.

13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.

According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.

The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.

Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.

In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g. self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.

Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.

14. Right to lodge a complaint with a data protection supervisory authority

As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.

15. Data protection for applications and in the application process

We collect and process Personal Data of applicants in the application process. Processing may also take place electronically. This is particularly the case if an applicant submits relevant application documents to us electronically, for example by email or via a web form on our or third-party websites.

For applicant data, the purpose of data processing is to carry out a review of the application in the application process. For this purpose, we process all data provided by you. Based on the data submitted as part of the application, we check whether you will be invited to an interview (part of the selection process). Then, in the case of generally suitable applicants, in particular during the interview, we process certain other Personal Data provided by you that is essential for our selection decision.

The legal basis for data Processing is Art. 6 (1) (b) GDPR, Art. 9 (2) (b) and (h) GDPR, Art. 88 (1) GDPR and national legislation.

If we do not conclude an employment contract with the applicant, the application documents will be deleted no later than six months after notification of the rejection decision, provided that no other legitimate interests of the Controller stand in the way of deletion. Another legitimate interest in this sense is, for example, the provision of evidence in legal proceedings.

You have the option of registering on our websites by providing Personal Data and/or filling out input masks. Which Personal Data is transmitted to us in the process is determined by the respective input mask used for registration or input. The Personal Data you enter will be processed exclusively for internal use by us and for our own purposes. However, we may pass on your Personal Data to one or more Processors, for example to parcel service providers, who also use your Personal Data exclusively for purposes that are attributable to us as the Controller. Disclosure may also take place if you have commissioned the disclosure from us. The legal basis is then Art. 6 (1) (b) GDPR.

When you register or enter data on our website, the IP address assigned by your internet service provider (ISP), the date and time of registration or entry may also be stored. This data is stored against the background that this is the only way to prevent misuse of our services and, if necessary, to make it possible to investigate criminal offenses. In this respect, the storage of this data is necessary for our security. The purpose of processing is the prevention and detection of misuse and the investigation of criminal offenses, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is in particular the protection of our information technology systems and the investigation of criminal offenses. This data is not disclosed to Third Parties unless there is a legal obligation to disclose it, or the disclosure serves the purpose of criminal prosecution.

The registration, entry and transmission of your Personal Data also enables us to offer you content or services which, due to the nature of the matter, can only be offered to registered persons or persons known to us. You are free to change the Personal Data provided during registration at any time or to have it completely deleted from our database. The purposes of processing are the receipt of data by us and the use of your data for further Processing, for communication with you and the illustration or implementation of the registration or input purposes. The legal basis is your Consent in accordance with Art. 6 (1) (a) GDPR and/or Art. 49 (1) (1) (a) GDPR.

By entering and transmitting your data, you voluntarily consent to the Processing of the Personal Data you have entered. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g. due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When giving your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.

Upon request, we will provide any Data Subject at any time with information about which Personal Data about the Data Subject is stored. We will also correct or delete Personal Data at the request or notice of the Data Subject, provided that this does not conflict with any statutory retention obligations or other reasons justifying Processing. All our employees are available to you as contact persons in this context.

Complianz - GDPR/CCPA Cookie Consent is a WordPress plugin that supports compliance with data protection regulations (GDPR and CCPA) by providing a user-friendly solution for managing cookie Consents. This plugin helps website operators to obtain and document legally required Consents for data Processing and cookie use from website visitors. It processes and stores information about users' Consent to cookies and their IP addresses.

The application is installed on our own IT infrastructure. We are the company operating the service.

Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Complianz - GDPR/CCPA Cookie Consent is to comply with data protection laws through the use of cookie Consent tools. Processing is based on Art. 6 (1) (c) GDPR, as the Processing is necessary for compliance with a legal obligation to which our organisation is subject.

The criteria for determining the duration for which the Personal Data is processed are the statutory or contractual retention periods. The use of Personal Data is required by law, as it is necessary to fulfill legal obligations in the area of data protection and Consent management. Users are required to indicate their cookie preferences or reject cookies, and this information must be stored to properly document the decision.

Further information about Complianz - GDPR/CCPA Cookie Consent can be found at https://complianz.io/.

18. Data protection provisions about the application and use of Google Site Verification

We use Google Site Verification service to verify our website with Google. This verification is a prerequisite for the use of other Google services such as Google Search Console, Google Analytics or Google Ads. As part of Site Verification, a verification token is integrated using various methods (e.g. HTML file, meta tag, DNS entry or Google Tag Manager) in order to prove ownership of the domain. When using the service, personal data may be processed, in particular in the form of IP addresses, technical access data and information about the domain, the website or the Google account used.

Processing is automated via Google servers. After successful verification, the website property is stored in the Google account of the verifying user.

The company that operates the service and therefore the recipient of the personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.

Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is the technical verification of domain ownership for the activation of Google services such as Search Console or Analytics. The processing is carried out on the basis of Art. 6 (1) (f) GDPR. The legitimate interest lies in the use of Google tools, the proper assignment of services to the domain and the technical protection of accounts against misuse.

The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is neither legally nor contractually required, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.

Further information and the applicable data protection provisions of Google may be retrieved under https://policies.google.com/privacy.

19. Data protection provisions about the application and use of Microsoft Purview

We use Microsoft Purview to manage, classify and monitor data in our IT environment with the aim of holistically implementing data protection regulations, security guidelines and compliance requirements. Microsoft Purview supports the identification of sensitive data, the implementation of data classification policies, the monitoring of data movements and the enforcement of protective measures and legal retention requirements. In this context, personal data can be processed, especially if it is contained in monitored files, emails, chat histories or databases. Processed data includes names, email addresses, user IDs, communication content, file content, metadata, access rights, timestamps, location data and usage histories.

Data processing is automated via Microsoft's cloud infrastructure and is tightly integrated into Microsoft 365 and other Microsoft services. Microsoft Purview systematically analyzes structured and unstructured data, creates reports, identifies data protection risks and enables targeted measures such as encryption, data loss prevention (DLP) or access restrictions. The collected data and results are used to implement company-wide compliance strategies and can be managed by authorized persons via the Microsoft Purview Compliance Portal.

The company that operates the service and thus the recipient of personal data is: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. For data subjects in the EU and EEA, Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Microsoft Limited, Microsoft Campus, Thames Valley Park, Reading, RG6 1WG, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Microsoft Schweiz GmbH, Seestrasse 356, 8038 Zurich, Switzerland.

Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of processing is to carry out data protection reviews and compliance monitoring, the classification of sensitive data, the implementation of statutory retention obligations, the identification of risks in the handling of personal data and the application of protection guidelines. The processing is carried out on the basis of Art. 6 (1) (f) GDPR. The legitimate interest lies in the data protection-compliant processing of information, compliance with legal requirements, the protection of sensitive data and the automated enforcement of internal protective measures.

The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide personal data, you may not be able to use our services or those of the company that operates the service.

Further information and the applicable data protection provisions of Microsoft Purview can be retrieved at https://privacy.microsoft.com/.

20. Data protection provisions about the application and use of Typeform

We use Typeform to create forms and conduct interactive surveys. Typeform enables us to collect information in a structured and user-friendly way. When using the service, personal data is processed, in particular when users fill out forms or interact with embedded elements on our website or by email. The data processed includes names, email addresses, answers to free text fields or multiple-choice questions, IP addresses, time stamps, location data, device data and browser information.

The collected data is used to carry out internal evaluations, to improve products and services, to process contact requests or applications and to send further information. The data is transmitted in encrypted form and stored on servers operated by Typeform. Processing is automated and can be customized or evaluated by us.

The company that operates the service and thus the recipient of personal data is: Typeform S.L., Calle Bac de Roda 163, 08018 Barcelona, Spain. The representative under national law in the United Kingdom is: Typeform UK Limited, 9th Floor, 107 Cheapside, London EC2V 6DN, United Kingdom.

Purposes for which personal data are to be processed and the legal basis for the processing: The processing is carried out for the creation, provision and evaluation of forms and surveys. Processing is carried out on the basis of Art. 6 (1) (a) GDPR, i.e., consent, or Art. 6 (1) (b) GDPR, i.e., for the performance of a contract to which the data subject is party, and Art. 6 (1) (f) GDPR. The legitimate interest lies in interactive and efficient communication with users, in data collection for the further development of our offers and in the analysis of user needs.

The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide personal data, you may not be able to use our services or those of the company that operates the service.

Further information and the applicable data protection provisions of Typeform may be retrieved under https://typeform.com/.

21. Data protection provisions about the application and use of Google Meet

Google Meet is a video conferencing service developed by Google LLC that enables users to conduct video conferences and online meetings. As part of Google Workspace, Google Meet provides a secure and reliable platform for businesses, educational institutions and individuals to promote communication and collaboration. The service supports features such as screen sharing, real-time captioning and integration with Google Calendar to make it easier to plan and conduct virtual meetings.

When using Google Meet, Personal Data such as names, email addresses, video images and audio recordings, as well as meeting data (such as participant lists, date and time of the meeting) are processed. This information is necessary to provide the video conferencing service, improve the user experience and ensure the security of the meetings.

The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.

Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of the video conferencing service. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the promotion of digital communication and collaboration.

The company that operates the serviceis based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the servicemay be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate guarantees from us.

The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.

Further information and the applicable data protection provisions of Google Meet may be retrieved under https://policies.google.com/privacy.

22. Data protection provisions about the application and use of Hostinger

Hostinger is a provider of web hosting services that enables us to operate our website securely and with high availability. Hostinger offers various hosting services, including shared hosting, VPS and cloud hosting. When using Hostinger, personal data such as name, e-mail address, payment information and IP addresses are processed, which are required to provide the hosting services. This data is used to manage user accounts, provide support and ensure website performance. Hostinger ensures high availability of our website and protects us from outages and attacks.The company that operates the service and thus the recipient of personal data is: Hostinger UAB, Jonavos g. 60C, LT-44192 Kaunas, Lithuania. The representative under national law in the United Kingdom is: Hostinger UK Limited, c/o Cogency Global (UK) Limited, 6 Lloyds Avenue, Suite 4cl, London, England, EC3N 3AX, United Kingdom.Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is the use and provision of web hosting services as well as the management and maintenance of servers and ensuring IT security and data protection. The processing is based on Art. 6 (1) (b) GDPR, as it is necessary for the performance of a contract to which the data subject is a party, and on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in ensuring IT security and data protection.The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.Further information and the applicable data protection provisions of Hostinger can be found at https://www.hostinger.com/.

23. Data protection provisions about the application and use of Cloudflare

Cloudflare offers a wide range of services to improve the security, performance and reliability of websites and web applications. Core features include DDoS protection, web application firewall, content delivery network services, secure DNS services and more. By using Cloudflare, we can protect our online presence from cyber-attacks, improve the loading speed of our website and ensure the overall availability of our services.When using Cloudflare services, data such as IP addresses, system configurations and network traffic information is processed. This information is necessary to ward off threats, optimize data traffic and provide insights into website usage.The company that operates the service and thus the recipient of personal data is: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. For data subjects in the EU and EEA, Cloudflare Netherlands B.V., Keizersgracht 62, 1015CS Amsterdam, Netherlands, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Cloudflare, Ltd., County Hall/The Riverside Building, Belvedere Road, London, SE1 7PB, United Kingdom.Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of services to secure and optimize websites and web applications. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in ensuring the security, performance and reliability of our online presence.The company that operates the serviceis based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. Cloudflare, Inc. may have concluded one of the EU standard contractual clauses with us. You can request a copy of the suitable or appropriate safeguards from us.The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.Further information and the applicable data protection provisions of Cloudflare, Inc. can be found at https://www.cloudflare.com.

24. Data protection provisions about the application and use of Font Awesome

Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.The company that operates the serviceis located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the servicemay have concluded one of the EU standard contractual clauses with us. You can request a copy of the suitable or appropriate guarantees from us.The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.Further information and the applicable data protection provisions of Font Awesome can be found at https://fontawesome.com.

25. Data protection provisions about the application and use of Canva

Canva is an online design and publishing platform that provides us with a wide range of tools and resources for creating visual content. Canva allows us to create professional designs. The platform provides access to an extensive library of templates, images and design elements that support the creation of content for our projects and communication channels.When using Canva, Personal Data such as names, email addresses, design preferences and usage data are processed. This information allows us to create individual accounts, save personalized designs and optimize experiences.The company that operates the service and thus the recipient of personal data is: Canva Pty Ltd, 110 Kippax St, Surry Hills NSW 2010, Australia. For data subjects in the EU and EEA, European Data Protection Office (EDPO), Ground Floor, 71 Lower Baggot Street, Dublin, D02 P593, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: European Data Protection Office UK (EDPO UK), 8 Northumberland Avenue, London WC2N 5BY, United Kingdom.Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of a platform for the creation and management of design content. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the use of an efficient and user-friendly design tool for professional purposes.The company that operates the serviceand thus the recipient of the Personal Data is based in a country that has been recognized by the European Commission as having an adequate level of data protection. Therefore, no additional guarantees are required for the transfer of data.The company that operates the serviceis located in a third country, namely Australia. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. Canva Pty Ltd may have entered into one of the EU standard contractual clauses with us. You can request a copy of the suitable or appropriate safeguards from us.The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.Further information and Canva's applicable data protection provisions can be found at https://www.canva.com.

26. Data protection provisions about the application and use of Cloudinary

Cloudinary offers a comprehensive cloud-based image and video management solution that allows us to easily upload, store, edit and deliver media content. The platform helps us to optimize the loading times of our website, determine the quality of our media content and provide a better user experience. By automating processes such as image compression and formatting and providing a reliable content delivery network, Cloudinary can significantly improve the performance of our online offerings.When using Cloudinary, Personal Data such as IP addresses and usage data are processed to provide and optimize the services. This information helps us to increase the efficiency of our media management and to ensure the global accessibility of our content.The company that operates the service and thus the recipient of personal data is: Cloudinary Ltd., 20 Aharon Bart St., Building C, 2nd floor, Petah Tikva, 4951448, Israel. For data subjects in the EU and EEA, Cloudinary Poland Sp. z o.o., Fabryczna Office Park, Budynek Alfa, piętro 9 Loftmill, Al. Pokoju 18, 31--564 Kraków, Poland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Cloudinary UK Ltd., 30 Old Bailey, London EC4M 7AU, United Kingdom.Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of media management services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving efficiency and the user experience.The company that operates the serviceis based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. Cloudinary, Inc. may have entered into one of the EU standard contractual clauses with us. You can request a copy of the suitable or appropriate safeguards from us.The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.Further information and the applicable data protection provisions of Cloudinary, Inc. can be found at https://cloudinary.com.

27. Data protection provisions about the application and use of Google Workspace

Google Workspace is a comprehensive suite of cloud-based productivity and collaboration tools. It includes a variety of applications such as Gmail, Google Docs, Google Sheets, Google Slides, Google Drive, Google Calendar and Google Meet that enable businesses, educational institutions and teams to collaborate, communicate and manage projects efficiently. Google Workspace provides seamless integration between its various services to create a productive work environment that is accessible from anywhere.

When using Google Workspace, Personal Data such as names, email addresses, calendar events, document content and communication data are processed. This information is necessary to provide the services, to enable collaboration and communication between users and to offer a personalized user experience.

The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.

Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize productivity and collaboration services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in promoting the efficiency, productivity and collaboration of teams and organizations.

The company that operates the serviceis based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the servicemay be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate guarantees from us.

The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.

Further information and the applicable data protection provisions of Google Workspace can be found at https://policies.google.com/privacy.

28. Data protection provisions about the application and use of LimeSurvey

LimeSurvey is an open-source survey software that enables users to create, publish and analyze individual online surveys and studies. The platform offers a wide range of question and survey types, flexible design options and extensive analysis tools. LimeSurvey is used worldwide by researchers, educational institutions, businesses and public organizations to collect data and gain insights.

When using LimeSurvey, Personal Data such as names, email addresses, answers to surveys and, depending on the survey settings, possibly other personal or sensitive information from participants is processed. This data is necessary to provide the survey functions, to enable participants to access surveys and to evaluate the results.

The company that operates the serviceand therefore the recipient of the Personal Data is: LimeSurvey GmbH, Papenreye 63, 22453 Hamburg, Germany.

Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and administration of online surveys. Processing is based on the Consent of the survey participants (Art. 6 (1) (a) GDPR) or on legitimate interests (Art. 6 (1) (f) GDPR), such as conducting scientific research, market research or collecting feedback on products and services.

The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.

Further information and the applicable data protection provisions of LimeSurvey can be found at https://www.limesurvey.org.

29. Data protection provisions about the application and use of Notion

Notion is an application for notes, projects, documents and databases that provides a central workspace for individuals and teams. With Notion, users can organize their work, manage knowledge, plan and document projects and visually structure complex ideas. The platform combines word Processing, spreadsheets, database functionality and Kanban boards into a single, seamlessly integrated user interface that offers flexibility and customizability for a variety of use cases.When using Notion, Personal Data such as names, email addresses, organizational data, usage data (e.g. how and when the application is used), content data (e.g. notes, documents, task lists) and payment information for subscription services are processed. This information is necessary to provide the services, manage user accounts, improve the platform and make support requests.The company that operates the service and thus the recipient of personal data is: Notion Labs, Inc., 2300 Harrison Street, San Francisco, CA 94110, USA. For data subjects in the EU and EEA, Notion Labs, Ireland Ltd., 13/18 City Quay, Dublin 2, Dublin, Ireland acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Notion Labs United Kingdom Ltd., 3rd Floor, 1 Ashley Road, Altrincham WA14 2DT, United Kingdom.Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of the Notion platform for notes, project management and documentation. Processing is based on the Consent of the user (Art. 6 (1) (a) GDPR), the performance of a contract (Art. 6 (1) (b) GDPR) to which the Data Subject is party and on legitimate interests (Art. 6 (1) (f) GDPR), such as the use and improvement of our services.The company that operates the serviceis based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the servicemay have concluded one of the EU standard contractual clauses with us. You can request a copy of the suitable or appropriate guarantees from us.The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.Further information and the applicable data protection provisions of Notion Labs, Inc. can be found at https://www.notion.so.

30. Data protection provisions about the application and use of Akismet

Akismet is a spam-fighting service that helps to detect and filter comment spam on websites and blogs. By integrating Akismet, we can ensure that the comment sections on our website remain free of unwanted spam, which improves the quality of discussions and increases the security of the platform.

When using Akismet, data such as the commenter's IP address, user agent, referrer, site URL (together with other information provided by the commenter, such as name, username, email address and the comment text) is transmitted to the Akismet service to analyze for potential spam.

The company that operates the service and thus the recipient of personal data is:

Automattic Inc., 60 29th Street 343, San Francisco, CA 94110, USA. For data subjects in the EU and EEA, Aut O'Mattic A8C Ireland Ltd., 25 Herbert Place, Dublin, D02 AY86, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR.

Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Akismet is to prevent and filter spam comments on our website. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in maintaining the integrity of the comment function and the security of the website.

The company that operates the serviceis based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the servicemay have concluded one of the EU standard contractual clauses with us. You can request a copy of the suitable or appropriate guarantees from us.

The criteria for determining the duration for which the Personal Data is processed are the statutory or contractual retention periods. The provision of Personal Data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. However, if you do not provide it, you may not be able to use the services.

Further information and the applicable data protection provisions of Akismet can be found at https://akismet.com.

31. Data protection provisions about the application and use of Advanced Custom Fields (ACF)

Advanced Custom Fields (ACF) is a plugin for WordPress that allows developers and website administrators to add custom fields and metadata to WordPress posts, pages and custom post types. This facilitates the customization of data inputs and improves content management on the website. ACF does not store any Personal Data but it does allow for the collection, storage and display of personal data that users can enter, depending on how the fields are configured.

The application is installed on our own IT infrastructure. We are the company operating the service.

Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using ACF is to use advanced customization capabilities for data management within WordPress. Processing is based on Art. 6 (1) (f) GDPR. Our legitimate interest lies in the optimization of content management and the personalization of the user experience on the website.

The criteria for determining the duration for which the Personal Data is processed are internal, statutory or contractual retention periods. The use of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. If you do not provide it, you may not be able to use our services, functionality or the plugin.

Further information about Advanced Custom Fields can be found at https://www.advancedcustomfields.com/.

32. Data protection provisions about the application and use of Complianz - Terms and Conditions

Complianz - Terms and Conditions is a WordPress plugin that helps website operators to generate and manage legally binding terms and conditions. The tool facilitates the creation of customizable terms and conditions that are specifically tailored to the legal requirements and individual situation of the website. The plugin does not collect any Personal Data but merely provides a platform where users can enter their own data to create relevant documents. However, these documents may contain Personal Data.

The application is installed on our own IT infrastructure. We are the company operating the service.

Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Complianz - Terms and Conditions is to use a tool to create and manage legally compliant terms and conditions for websites to comply with legal requirements. Processing is based on Art. 6 (1) (c) GDPR, as Processing is necessary for compliance with a legal obligation to which our organisation is subject.

The criteria for determining the duration for which the Personal Data is processed are internal, statutory or contractual retention periods. The use of Personal Data is required by law or contract or is necessary for the conclusion of a contract. You are obliged to provide us with Personal Data for this Processing activity.

Further information about Complianz - Terms and Conditions can be found at WordPress.org.

33. Data protection provisions about the application and use of Contact Form 7

Contact Form 7 is a plugin for WordPress that allows us to create and manage flexible contact forms. The plugin collects data that users enter into forms, such as names, email addresses, messages and other specific information required for communication or inquiry capture. This data is used to process requests and respond to user communications.

The application is installed on our own IT infrastructure. We are the company operating the service.

Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Contact Form 7 is the use of online contact forms through which you can get in touch with us. Processing is based on Art. 6 (1) (f) GDPR. Our legitimate interest lies in efficient and secure communication between users and us.

The criteria for determining the duration for which the Personal Data is processed are internal, statutory or contractual retention periods. The use of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. If you do not provide it, you may not be able to use our services, functionality or the plugin.

Further information about Contact Form 7 can be found at https://contactform7.com.

34. Data protection provisions about the application and use of Flickr

Flickr is an online photo and video sharing platform that allows photographers, artists and enthusiasts to share their visual creations with a global community. In addition to the ability to upload photos and videos, Flickr offers extensive features for organizing, tagging and copyrighting content. Users can join groups, hold discussions and admire and comment on the work of others.

When using Flickr, Personal Data such as names, email addresses, profile information, uploaded content and interaction data are processed. This information is necessary to create and manage user accounts, personalize the service, ensure security and provide an interactive community environment.

The company that operates the service and thus the recipient of personal data is: Flickr, Inc., 67 E Evelyn Ave, Ste 200, Mountain View, CA 94041, USA. For data subjects in the EU and EEA, DP-Dock GmbH, Attn: Flickr Inc., Ballindamm 39, 20095 Hamburg, Germany, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: DP Data Protection Services UK Ltd., Attn: Flickr Inc., 16 Great Queen Street, Covent Garden, London, WC2B 5AH, United Kingdom.

Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of the photo and video sharing service. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the promotion of creative expression and the development of an engaged photography and video community.

The company that operates the serviceis based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. Flickr, Inc. may have concluded one of the EU standard contractual clauses with us. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.

Further information and the applicable data protection provisions of Flickr may be retrieved under https://www.flickr.com.

35. Data protection provisions about the application and use of Instagram

Instagram is a widely used social network that allows users to share photos and videos, post stories, and interact with followers and friends. Instagram offers a variety of features, including direct messages, IGTV for longer videos, Instagram Live for real-time broadcasts and a Discover page to find new content and users.When using Instagram, Personal Data such as names, email addresses, telephone numbers, user content (photos, videos, comments, etc.), location data, usage information and, in some cases, payment information is processed. This data helps to provide the service, ensure the security of the platform, offer personalized advertising and improve the user experience.The company that operates the service and thus the recipient of personal data is: Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA. For data subjects in the EU and EEA, Meta Platforms Ireland Ltd., Merrion Road, Dublin D04 X2K5, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Meta Platforms Technologies UK Ltd, 10 Brock Street, Regent's Place, London, NW1 3FG, United Kingdom.Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of the social network functions. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, where our legitimate interest lies in the improvement and personalization of the user experience, the provision of customer support and ensuring the security and integrity of the platform, as well as in the use of the platform and marketing.The company that operates the serviceis based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the servicemay be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate guarantees from us.The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.Further information and the applicable data protection provisions of Instagram can be viewed at https:// instagram.com.

36. Data protection provisions about the application and use of LinkedIn

LinkedIn is a social network for professional contacts and career development. The platform allows users to create a professional profile, network with colleagues, business partners and potential employers, share professional experiences and skills, and keep up to date with industry news. LinkedIn also provides tools for companies and recruiters to source talent, post job ads and build a brand presence.

When using LinkedIn, Personal Data such as names, email addresses, professional titles and experience, educational background, skills, interests and platform usage data are processed. This information is necessary to provide and use the service, to create networking opportunities, to present personalized content and job offers and to ensure the security of user data.

The company that operates the serviceand thus the recipient of the Personal Data is: LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.

Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of network and career services. Processing is based on the Consent of the user (Art. 6 (1) (a) GDPR), the performance of a contract (Art. 6 (1) (b) GDPR) to which the Data Subject is party and on legitimate interests (Art. 6 (1) (f) GDPR), such as marketing and recruitment.

The company that operates the serviceis based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the servicemay be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate guarantees from us.

The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.

Further information and the applicable data protection provisions of LinkedIn Corporation can be found at https://www.linkedin.com.

37. Data protection provisions about the application and use of TikTok

TikTok, a platform for short video clips that enjoys great popularity worldwide, enables users to create, share and discover creative content. Users can dance, sing, perform art or participate in trends on TikTok and interact with a global community.When using TikTok, Personal Data such as names, email addresses, telephone numbers, dates of birth, profile information, user content (videos, comments), location data and information from social networks are processed. This data is required to provide the services, personalize the platform, enable user interactions and improve support.The company that operates the service and thus the recipient of personal data is: TikTok Pte. Ltd., 1 Raffles Quay, No. 26-10, South Tower, 048583, Singapore. For data subjects in the EU and EEA, TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London, EC1A 9HP, United Kingdom.Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of data processing is the use of the video platform. Processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR, to which the Data Subject is a party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the use of a global platform for advertising and increasing our market presence.The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.Further information and the applicable data protection provisions of TikTok may be retrieved under https://www.tiktok.com.

38. Data protection provisions about the application and use of YouTube

YouTube is a video sharing and viewing platform used by individuals, artists, businesses and media companies to publish a variety of content such as music videos, vlogs, educational material and much more. YouTube offers users the ability to upload, share, comment and interact with a broad community.

When using YouTube, Personal Data such as IP addresses, user interactions (e.g. videos viewed, comments), location data (if enabled for services) and information from linked Google accounts are processed. This information is required to provide personalized content and advertising, enable user interactions, keep the platform secure and improve the user experience.

The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.

Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of data processing lies in the use of the video sharing services. Processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR, to which the Data Subject is a party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the use of an efficient video platform, the improvement of the user experience, the use of personalized advertising and the use of embedded videos on our website.

The company that operates the serviceis based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the servicemay be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate guarantees from us.

The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the serviceor statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the servicewith Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.

Further information and the applicable data protection provisions of YouTube can be found at https://policies.google.com.

39. Data protection provisions about the application and use of Stripe

Stripe is a technology company that provides powerful and flexible tools for e-commerce, including payment processing, billing, and financial management solutions. Stripe enables businesses of all sizes to accept and process online payments, manage subscriptions, and perform fraud prevention. The platform is known for reducing the complexity of financial transactions and making them more secure and user-friendly.When using Stripe services, Personal Data such as names, addresses, email addresses, telephone numbers, bank and payment information and transaction data are processed. This information is necessary to provide payment services, prevent fraud, provide customer support and comply with legal requirements.The company that operates the service and thus the recipient of personal data is: Stripe, Inc., 354 Oyster Point Boulevard, San Francisco, CA 94080, USA. For data subjects in the EU and EEA, Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Stripe Payments UK Ltd., 9th Floor, 107 Cheapside, London, EC2V 6DN, United Kingdom.Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of data processing lies in the use of payment processing via Stripe. Processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR, to which the Data Subject is a party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the improvement of our services, fraud prevention, the use of efficient payment applications, and compliance with legal requirements.The company that operates the serviceis based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the servicemay have concluded one of the EU standard contractual clauses with us. You can request a copy of the suitable or appropriate guarantees from us.The criteria for determining the duration for which the Personal Data is processed are the statutory or contractual retention periods. The provision of Personal Data is required by law or contract or is necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data for this Processing activity. However, if you do not provide it, you will not be able to use our services.Further information and the applicable data protection provisions of Stripe may be retrieved under https://stripe.com.

Diese Datenschutzerklärung wurde durch die Nutzung eines Generators erstellt, der gemeinsam von Fachanwälten für Internetrecht, Datenschutzberatern und der ISO 42001 Zertifizierungsstelle entwickelt wurde.

For more information, please visit the website of the DGD Deutsche Gesellschaft für Datenschutz EOOD at dg-datenschutz.de or contact the at info@dg-datenschutz.de